Secure Route Discovery Node and Policing Mechanism
Abstract
A computer implemented method and computer program product for obtaining a secure route. A trusted host sets a node security association for a trusted host. The trusted host receives, at the trusted host, a client communication request directed to a destination host. The trusted host builds a secure route query comprising a trusted host address, a destination host address, and at least one security level, to form at least one secure route. The trusted host sends packets from the trusted host to the destination host based on the at least one secure route. The packets are responsive to the client communication request, and the packets each have a security label that matches the security level.
Claims
exact text as granted — not AI-modified1 . A computer implemented method for identifying a source router, the computer implemented method comprising:
transmitting a multicast packet, wherein the multicast packets defines a security level and neighbor secure router for a secure router; receiving at least one packet above the security level associated with the secure router; and responsive to receiving the at least one packet having a classification level above the security level, transmitting a source address of the at least one packet to a secure route discovery node.
2 . The computer implemented method of claim 1 , further comprising:
setting an address of the secure route discovery node; and wherein transmitting the source address comprises transmitting the source address to the address of the secure route discovery node.
3 . The computer implemented method of claim 1 , wherein the at least one packet conforms to multilevel security standard.
4 . The computer implemented method of claim 1 , further comprising:
responsive to receiving the at least one packet having a classification level above the security level, dropping the at least one packet.
5 . The computer implemented method of claim 1 , further comprising:
receiving at least one packet at or below the clearance level associated with the secure router; and transmitting the at least one packet at or above the clearance level.
6 . The computer implemented method of claim 5 , wherein transmitting the at least one packet is by using a strict source route internet protocol.
7 . A computer implemented method for obtaining a secure route, the computer implemented method comprising:
setting a node security association for a trusted host; receiving, at the trusted host, a client communication request directed to a destination host; building a secure route query comprising a trusted host address, a destination host address, and at least one security level, to form at least one secure route; and sending packets from the trusted host to the destination host based on the at least one secure route, wherein the packets are responsive to the client communication request, and the packets each have a security label that matches the security level.
8 . The computer implemented method of claim 7 , wherein sending packets further comprises:
setting a strict source route option on each packet.
9 . The computer implemented method of claim 7 , wherein building further comprises:
determining whether the destination host is described in a secure route cache at the trusted host; and responsive to a determination that the destination host is in the secure route cache, forming the secure route based on the secure route cache.
10 . The computer implemented method of claim 7 , wherein building further comprises:
determining whether the destination host is described in a secure route cache; responsive to a determination that the destination host is not in the secure route cache, transmitting the secure route query to a secure route discovery host; receiving a secure route discovery node response; determining whether the secure route discovery node response is non-empty; and responsive to a determination that the secure route discovery node response is non-empty, storing at least one secure route of the secure route discovery node response to the secure route cache based on the secure route discovery node response.
11 . The computer implemented method of claim 10 , further comprises:
setting a cache time for the at least one secure route.
12 . The computer implemented method of claim 11 , further comprising:
determining a cache time expiration with respect to at least one secure route; and responsive to a determination that the cache time has expired, deleting the at least one secure route from the secure route cache.
13 . The computer implemented method of claim 10 , further comprising:
responsive to receiving a secure route discovery node response, caching the at least one secure route in the secure route cache response for a tunable cache time.
14 . A computer implemented method to direct at least one secure router, the method comprising:
receiving a secure route query from a trusted host, the secure route query comprising a trusted host address, a destination host address and a one classification level; looking up at least one path having as endpoints, a trusted host and a destination host; and responsive to finding a path, transmitting a secure route discovery node response.
15 . The computer implemented method of claim 14 , wherein looking up at least one path further comprises:
finding a network segment having one endpoint selected from the group consisting of trusted host and destination host, the network segment having a clearance level at least as high as the one classification level such that the network segment and at least one additional network segments interconnect trusted host and destination host, wherein the each additional network segment has endpoints each having a clearance level at least as high as the one classification level.
16 . The computer implemented method of claim 14 , wherein looking up the at least one path further comprises:
locating only one or more inadequate paths to interconnect trusted host and destination host via secure routers having clearance levels at or above the classification level; and responsive to locating only one or more inadequate paths, transmitting the secure route discovery node response as a packet to the trusted host, the packet having an empty string.
17 . The computer implemented method of claim 14 , further comprising:
receiving a multicast packet having a secure router and a clearance level associated with the secure router; and building a secure routes database having at least one network segment having the secure router as an endpoint, wherein the at least one network segment is associated with a clearance level at or below the clearance level associated with the secure route discovery node, wherein the looking up is with reference to the secure routes database.
18 . A computer program product for obtaining a secure route, the computer program product comprising: a computer usable medium having computer usable program code embodied therewith, the computer program product comprising:
computer usable program code configured to set a node security association for a trusted host; computer usable program code configured to receive, at the trusted host, a client communication request directed to a destination host; computer usable program code configured to build a secure route query comprising a trusted host address, a destination host address, and at least one security level, to form at least one secure route; and computer usable program code configured to send packets from the trusted host to the destination host based on the at least one secure route, wherein the packets are responsive to the client communication request, and the packets each have a security label that matches the security level.
19 . The computer program product of claim 18 , wherein sending packets further comprises:
computer usable program code configured to set a strict source route option on each packet.
20 . The computer program product of claim 18 , wherein building further comprises:
computer usable program code configured to determine whether the destination host is described in a secure route cache at the trusted host; and computer usable program code configured to form the secure route based on the secure route cache, responsive to a determination that the destination host is in the secure route cache.
21 . The computer program product of claim 18 , wherein building further comprises:
computer usable program code configured to determine whether the destination host is described in a secure route cache; computer usable program code configured to transmit the secure route query to a secure route discovery host responsive to a determination that the destination host is not in the secure route; computer usable program code configured to receive a secure route discovery node response; computer usable program code configured to determine whether the secure route discovery node response is non-empty; and computer usable program code configured to store at least one secure route of the secure route discovery node response to the secure route cache based on the secure route discovery node response, responsive to a determination that the secure route discovery node response is non-empty.
22 . The computer program product of claim 21 , further comprising:
computer usable program code configured to set a cache time for the at least one secure route.
23 . The computer program product of claim 22 , further comprising:
computer usable program code configured to determine a cache time expiration with respect to at least one secure route; and computer usable program code configured to delete the at least one secure route from the secure route cache, responsive to a determination that the cache time has expired.
24 . The computer program product of claim 21 , further comprising:
computer usable program code configured to cache the at least one secure route in the secure route cache response for a tunable cache time, responsive to receiving a secure route discovery node response.Join the waitlist — get patent alerts
Track US2011066851A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.